Hackers Spend Nearly $7 Million on Expired Domains
Sable Squirrel is estimated to have spent over $7 million on expired domains used for streaming, gambling and malware infrastructure.
Expired domain names might seem worthless once their owners stop paying for them. For cybercriminals, however, some can still be worth a lot of money.
Researchers at Infoblox Threat Intel have identified a group known as Sable Squirrel that controls more than 10,000 domains. The group is estimated to have spent more than $7 million acquiring expired domains, which are now being used for everything from illegal sports streaming and gambling to malware infrastructure.
The $7 million figure is an estimate rather than a confirmed spending total. Researchers were able to verify the cost of around 160 domains worth more than $430,000 and used that data to estimate the group’s spending across its much larger collection.
There is a reason criminals are willing to spend money on domains that other people have abandoned.
An older domain can still have backlinks, search engine history and visitors that were built up over years. In some cases, people may continue visiting an address long after its original website has disappeared.
That existing history can be useful to someone trying to make a new operation look less suspicious.
Infoblox estimates that around 50,400 expired domains are re-registered every day across generic top-level domains. When country-code domains are included, the figure rises to around 65,000 a day.
For Sable Squirrel, that has become a business in its own right.
A large part of the group’s operation revolves around illegal sports streaming.
Infoblox linked more than 10,000 domains to streaming brands including Xoilac, Cakhia, 90phut, Socolive and MiTom. The sites offer live football streams and other features aimed at keeping visitors on the platforms.
But the streams appear to be only part of the business.
Visitors can be redirected toward betting platforms such as VSBet, ColaScore and 8xbet. Infoblox assesses with high confidence that Sable Squirrel controls or operates these gambling platforms rather than simply sending visitors to unrelated companies.
The researchers also found evidence that the operation targets users across several Asian countries. Infoblox believes Sable Squirrel is an Asian and likely transnational operation, with strong indicators pointing toward Vietnam.
This is where the operation gets considerably more interesting.
Infoblox found more than 31,000 malware samples communicating with domains controlled by Sable Squirrel.
Those samples included several well-known remote access trojans, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos and njRAT.
Researchers also found samples carrying signatures associated with HiddenTear ransomware. There is an important caveat here, though: Infoblox did not confirm that the samples were actually being used to deploy ransomware against victims in the wild.
Instead, the researchers found that some Sable Squirrel domains were being used as command-and-control infrastructure for malware.
So the same domain that appears to be hosting a football stream can also be communicating with an infected computer in the background.
Other domains in the group’s collection also have legitimate histories.
Infoblox identified domains including healthymagination.com, which was associated with General Electric’s former health initiative, and rezilion.com, which was previously connected to a cybersecurity company whose core assets were acquired by GitLab.
The criminals aren’t necessarily interested in the old businesses themselves. What they want is the history attached to the domain.
Years of backlinks, search results and existing traffic can be much more useful than starting with a completely new address.
Once Sable Squirrel gets hold of a domain, it can put it to work surprisingly quickly.
Infoblox found that 24% of the dropcatch domains it examined became active on the same day they were re-registered. Another 76% were active within seven days, and 94% were active within two weeks.
The group uses both expired domains and newly registered lookalike domains.
The expired ones provide established history and traffic, while newer domains give the operators a steady supply of addresses that can be replaced if necessary.
Sable Squirrel isn’t the only group taking advantage of expired domains.
Infoblox is also tracking groups it calls Stuffy Squirrel, Shady Squirrel and Swiping Squirrel.
Their operations aren’t identical, but they share the same basic idea: acquire domains that already have some history and make use of whatever traffic or reputation remains.
Shady Squirrel, for example, has been linked to traffic associated with SocGholish, a malware operation known for fake software update campaigns. Researchers have also observed traffic being sent toward initial-access brokers and technical-support scams.
The interesting part of the research is how much value can remain attached to a domain after its original website disappears.
Old links don’t automatically disappear. Search engines may still have the address indexed, people may still have bookmarks pointing to it, and other websites may continue linking to it.
For criminals, all of that can be useful.
Sable Squirrel has taken that idea and built a large operation around it, combining expired domains with illegal sports streaming, gambling and malware infrastructure.
A domain that looks completely abandoned to the average person can still have plenty of value to someone willing to buy it.
Source: InfoBlox
Related articles :
__Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__